US2013031631A1PendingUtilityA1

Detection of unauthorized device access or modifications

Assignee: LENOVO SINGAPORE PTE LTDPriority: Jul 25, 2011Filed: Jul 25, 2011Published: Jan 31, 2013
Est. expiryJul 25, 2031(~5 yrs left)· nominal 20-yr term from priority
G06F 21/554G06F 21/575
41
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Devices, methods and products are described that provide for recording an unauthorized event, such as rooting, on an information handling device. One aspect provides a method comprising determining whether at least one unauthorized event has occurred on an information handling device; setting at least one unauthorized event flag stored on the information handling device responsive to an unauthorized event; and allowing external access to the at least one unauthorized event flag. Other embodiments and aspects are also described herein.

Claims

exact text as granted — not AI-modified
1 . An information handling device comprising:
 one or more processors;   a display device accessible by the one or more processors;   a memory in operative connection with the one or more processors;   wherein, responsive to execution of program instructions accessible to the one or more processors, the one or more processors are configured to:   determine whether at least one unauthorized event has occurred on the information handling device;   set at least one unauthorized event flag responsive to an unauthorized event; and   allow external access to the at least one unauthorized event flag.   
     
     
         2 . The information handling device of  claim 1 , wherein the information handling device comprises a cell phone. 
     
     
         3 . The information handling device of  claim 1 , wherein the at least one unauthorized event comprises rooting the information handling device. 
     
     
         4 . The information handling device of  claim 1 , wherein the at least one unauthorized event comprises detection of installation of unauthorized software on the information handling device. 
     
     
         5 . The information handling device of  claim 1 , wherein the at least one unauthorized event flag comprises at least one bit reserved in firmware running on the information handling device. 
     
     
         6 . The information handling device of  claim 5 , wherein the firmware running on the information handling device comprises embedded controller firmware. 
     
     
         7 . The information handling device of  claim 1 , wherein the at least one unauthorized event flag is transmitted externally responsive to being set. 
     
     
         8 . The information handling device of  claim 7 , further communicating to an external database:
 the external database comprising:   at least one database configured to store information associated with the information handling device; and   at least one receiver configured to receive a transmitted unauthorized event flag;   wherein the at least one receiver updates the at least one database for the information handling device response to receiving a transmitted unauthorized event flag.   
     
     
         9 . The information handling device of  claim 1 , wherein determining whether at least one unauthorized event has occurred on the information handling device comprises determining whether at least one partition hash value matches at least one signed value. 
     
     
         10 . The information handling device of  claim 9 , wherein the at least one partition hash value comprises at least one system partition hash value and at least one boot partition hash value. 
     
     
         11 . A method comprising:
 determining whether at least one unauthorized event has occurred on an information handling device;   setting at least one unauthorized event flag stored on the information handling device responsive to an unauthorized event; and   allowing external access to the at least one unauthorized event flag.   
     
     
         12 . The method of  claim 11 , wherein the information handling device comprises a cell phone. 
     
     
         13 . The method of  claim 11 , wherein the at least one unauthorized event comprises rooting the information handling device. 
     
     
         14 . The method of  claim 11 , wherein the at least one unauthorized event comprises detection of installation of unauthorized software on the information handling device. 
     
     
         15 . The method of  claim 11 , wherein the at least one unauthorized event flag comprises at least one bit reserved in firmware running on the information handling device. 
     
     
         16 . The method of  claim 15 , wherein the firmware running on the information handling device comprises embedded controller firmware. 
     
     
         17 . The method of  claim 11 , wherein the at least one unauthorized event flag is transmitted externally responsive to being set. 
     
     
         18 . The method of  claim 17 , wherein the information handling device is configured to communicate with at least one external database, the at least one external database comprising:
 at least one database configured to store information associated with the information handling device; and   at least one receiver configured to receive a transmitted unauthorized event flag;   wherein the at least one receiver updates the at least one database for the information handling device response to receiving a transmitted unauthorized event flag.   
     
     
         19 . The method of  claim 1 , wherein determining whether at least one unauthorized event has occurred on the information handling device comprises determining whether at least one partition hash value matches at least one signed value. 
     
     
         20 . A program product comprising:
 a storage medium having program code embodied therewith, the program code comprising:   program code configured to determine whether at least one unauthorized event has occurred on an information handling device;   program code configured to set at least one unauthorized event flag stored on the information handling device responsive to an unauthorized event; and   program code configured to allow external access to the at least one unauthorized event flag.

Join the waitlist — get patent alerts

Track US2013031631A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.